# Threat Intel Brief — 23 May 2026
TL;DR
- Cisco SD-WAN vulnerability (CVE-2026-20127) exploited since 2023; immediate patching required for all Catalyst SD-WAN controllers and managers.
- CISA contractor intentionally leaked AWS GovCloud credentials on public GitHub, prompting Congressional inquiry and emergency credential rotation.
- Multiple zero-day and critical vulnerabilities under active exploitation: Trend Micro Apex One, Langflow (CVE-2025-34291), and Drupal SQL injection flaws targeted in the wild.
- Law enforcement dismantles criminal infrastructure: First VPN Service (used by 25 ransomware groups) and KimWolf botnet (2 million devices) taken down in coordinated operations.
- Iranian APT Screening Serpens targets defense and technology sectors with custom RAT malware and AppDomainManager hijacking techniques.
---
Critical Threats
Cisco SD-WAN Manager Authentication Bypass (CVE-2026-20127)
What happened: Cisco disclosed multiple critical vulnerabilities in Catalyst SD-WAN controllers and SD-WAN Manager on 25 February 2026. CVE-2026-20127 has been actively exploited in the wild since 2023, enabling attackers to gain administrative access to SD-WAN infrastructure.
Impact: Attackers with administrative access can reconfigure WAN routing, intercept traffic, deploy malware, or disrupt connectivity across entire SD-WAN fabrics. The three-year exploitation window suggests prolonged adversary access to vulnerable environments. Organizations running Cisco SD-WAN face immediate risk of network compromise and lateral movement.
Recommendations:
- Apply Cisco security patches released 25 February 2026 immediately to all SD-WAN controllers and managers.
- Audit SD-WAN logs since 2023 for unauthorized administrative access, configuration changes, or anomalous authentication events (Windows Event ID 4624, 4625; Sysmon Event ID 1 for unusual process execution).
- Review all administrative accounts and recent configuration changes for signs of persistence mechanisms.
- Implement network segmentation to isolate SD-WAN management interfaces from untrusted networks.
---
CISA Contractor Exposes AWS GovCloud Credentials
What happened: A CISA contractor intentionally published AWS GovCloud keys and agency secrets on a public GitHub repository, creating an intelligence windfall for adversaries. Congressional lawmakers have demanded answers as CISA works to invalidate leaked credentials and contain the breach.
Impact: Exposed credentials provide potential access to sensitive U.S. government cloud infrastructure used for federal operations. The breach compromises CISA's operational security and potentially affects inter-agency trust and government cloud environment integrity. Any adversary monitoring public code repositories could have accessed these credentials before remediation.
Recommendations:
- Implement automated secret scanning on all code repositories using GitHub Advanced Security, GitGuardian, or TruffleHog to detect credential exposure before public commits.
- Enforce least-privilege access and time-bound credentials for contractors accessing sensitive cloud infrastructure, with frequent key rotation.
- Deploy Data Loss Prevention controls and egress monitoring to detect exfiltration to code repositories or web services.
- Establish continuous behavioral analytics to flag anomalous credential access, downloads, or repository commits by insiders with privileged access.
---
Trend Micro Apex One Zero-Day Under Active Exploitation
What happened: Trend Micro disclosed a zero-day vulnerability in Apex One endpoint security software being actively exploited against Windows systems. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog, confirming real-world attacks.
Impact: Active exploitation of endpoint protection platforms enables attackers to achieve complete endpoint control, credential theft, lateral movement, and disabling of security mechanisms. Organizations relying on Apex One for endpoint security face immediate risk of compromise. The targeting of security software itself amplifies risk across enterprise environments.
Recommendations:
- Check Trend Micro security bulletins for emergency patches or hotfixes and apply immediately to all Apex One servers and agents.
- Review Apex One server logs and Windows Event Logs (Event IDs 4688, 4689 for process creation/termination; Sysmon Event ID 1, 3, 7) for suspicious authentication attempts, unusual process execution, or unexpected network connections.
- Implement network segmentation to isolate Apex One management servers from general network access.
- If patches are unavailable, restrict management console access to trusted IP addresses only as a temporary compensating control.
---
Langflow Origin Validation Flaw (CVE-2025-34291)
What happened: CISA added CVE-2025-34291 (CVSS 9.4) in Langflow to its Known Exploited Vulnerabilities catalog. The origin validation error is confirmed to be under active exploitation in the wild.
Impact: Origin validation errors typically allow attackers to bypass security controls or execute unauthorized actions. With a CVSS score of 9.4, this vulnerability likely enables remote code execution or authentication bypass. Federal agencies are under binding operational directive to patch; private sector organizations should treat with equivalent urgency.
Recommendations:
- Identify all Langflow instances in your environment immediately and apply vendor patches as soon as available.
- Review authentication logs and access patterns for Langflow systems for signs of compromise since vulnerability disclosure.
- If patches are unavailable, isolate affected systems or implement network segmentation and strict access controls.
- Monitor CISA KEV catalog and vendor advisories for updated guidance and specific version information.
---
Cisco Secure Workload REST API Flaw (CVE-2026-20223)
What happened: Cisco patched a critical CVSS 10.0 vulnerability in Secure Workload (formerly Tetration) that allows unauthenticated remote attackers to access sensitive data through insufficient validation and authentication in REST API endpoints.
Impact: Unauthenticated attackers can remotely access application dependency maps, network flow data, policy configurations, and potentially credentials or security telemetry. CVSS 10.0 indicates maximum severity with no mitigating factors—network-accessible with no authentication required. Immediate patching is required to prevent data exfiltration and reconnaissance of internal network architecture.
Recommendations:
- Identify all Cisco Secure Workload deployments and apply patches for CVE-2026-20223 within 24 hours.
- Review REST API access logs for unauthorized access attempts or anomalous data queries from unexpected source IPs.
- Restrict network access to Secure Workload REST API endpoints using firewall rules or ACLs to trusted management networks only.
- Monitor Cisco security advisories for additional indicators of compromise and supplemental guidance.
---
Drupal Core SQL Injection Under Active Exploitation
What happened: Drupal warned that attackers are actively exploiting a critical SQL injection vulnerability announced earlier this week. CERT-BE issued an urgent advisory requiring immediate patching of all Drupal installations.
Impact: SQL injection vulnerabilities enable attackers to read, modify, or delete database contents, potentially leading to full site compromise, data exfiltration, administrative account takeover, and malware injection. Given active exploitation and critical severity, unpatched Drupal sites face immediate risk of breach.
Recommendations:
- Apply Drupal security updates immediately—check Drupal.org security advisories for patches released this week.
- Identify all Drupal installations using asset inventory or network scanning and verify patch status.
- Review Drupal database and web server logs for suspicious SQL query patterns or unauthorized access attempts from the past seven days.
- If immediate patching is not possible, place Drupal sites behind a web application firewall with SQL injection rules enabled or take offline until patched.
- After patching, rotate database credentials and review user accounts for unauthorized additions or privilege escalations.
---
Additional Critical Vulnerabilities Requiring Immediate Action
Ivanti EPMM: Two critical unauthenticated remote code execution vulnerabilities (CVE: see source) are under limited exploitation. Organizations using Ivanti Endpoint Manager Mobile must apply patches immediately or isolate EPMM servers from internet access.
Cisco Secure Email Gateway: Critical vulnerability (CVE: see source) with no patch available as of December 2025. Organizations must review Cisco advisory for compromise indicators and implement interim mitigations.
React Server Components: Critical RCE flaw (CVE: see source) disclosed 3 December 2025 allows unauthenticated remote code execution via crafted HTTP requests. All applications using React Server Components, Next.js, or Remix require immediate updates.
Microsoft WSUS: Critical RCE vulnerability (CVE: see source) with public proof-of-concept exploit. Apply Microsoft's out-of-band update to all WSUS servers immediately.
Ubiquiti UniFi OS: Three maximum severity vulnerabilities (CVE: see source) enable unauthenticated remote exploitation. Update all UniFi OS devices and restrict management interface access.
---
Threat Actor Activity
Insider Threat: CISA Contractor Data Leak
A CISA contractor intentionally published AWS GovCloud keys and agency secrets on a public GitHub account, representing a classic insider threat scenario within a critical U.S. government cybersecurity organization. The breach exposes sensitive government cloud infrastructure and highlights persistent vulnerabilities in insider threat programs and third-party contractor oversight. Congressional involvement signals potential legislative responses regarding contractor accountability and federal cloud security standards.
Iranian APT: Screening Serpens
Unit 42 reports that Screening Serpens, an Iranian state-aligned APT group, is conducting espionage campaigns targeting technology and defense sectors in 2026. The group employs sophisticated techniques including AppDomainManager hijacking for execution and persistence, and deploys custom Remote Access Trojan variants for command and control. The targeting aligns with Iranian strategic intelligence requirements for defense capabilities information and advanced technology insights.
Belarus-Aligned: Ghostwriter Targets Ukraine
Ghostwriter (also tracked as UAC-0057 and UNC1151), a Belarus-aligned threat actor, is conducting phishing campaigns against Ukrainian government entities using lures themed around the Prometheus online learning platform. CERT-UA documented the activity, which involves spear-phishing emails designed to harvest credentials or deliver malware. This campaign continues Ghostwriter's established pattern of targeting Ukrainian state institutions amid ongoing geopolitical tensions.
Supply Chain Attack: Megalodon GitHub Campaign
Researchers disclosed an automated campaign called Megalodon that pushed 5,718 malicious commits to 5,561 GitHub repositories within six hours. The attacker used throwaway accounts and forged identities to inject malicious GitHub Actions workflows containing base64-encoded bash payloads designed to exfiltrate CI/CD environment data, secrets, and API keys. The mass-scale approach indicates indiscriminate targeting to maximize credential harvesting opportunities.
Cloud Intrusion: ROADtools Abuse
Multiple threat actors, including nation-state affiliated groups, are leveraging the open-source ROADtools framework for Azure AD reconnaissance and cloud-focused intrusions. The legitimate Azure AD toolkit is being repurposed for malicious enumeration of users, groups, roles, and service principals to enable privilege escalation and persistent access to enterprise cloud infrastructure. The tool's legitimate appearance aids in evading detection by mimicking normal administrative activity.
Multi-Stage Attack: F5 BIG-IP and Confluence Compromise
An unattributed threat actor exploited an exposed F5 BIG-IP edge appliance to gain initial access, then pivoted to an internal Atlassian Confluence server for credential theft and identity compromise. The actor attempted Kerberos relay attacks and lateral movement techniques, which were detected and blocked by Microsoft Defender. The campaign demonstrates moderate technical sophistication and familiarity with enterprise IT environments.
---
Geopolitical Context
Law Enforcement Operations
First VPN Service Dismantled: Authorities in Europe and North America dismantled First VPN Service, a criminal VPN infrastructure used by approximately 25 ransomware groups to obscure attack origins. The operation, led by France and the Netherlands with international cooperation since December, represents a strategic shift toward dismantling enabling infrastructure rather than pursuing individual threat groups alone.
KimWolf Botnet Takedown: U.S. and Canadian authorities arrested Jacob Butler, a 23-year-old Canadian national, for operating the KimWolf DDoS botnet that infected nearly two million devices worldwide. The arrest demonstrates continued North American cross-border cooperation targeting cybercrime infrastructure and may produce a short-term deterrent effect on botnet operators in Western jurisdictions.
Netherlands Infrastructure Seizure: Dutch financial crime investigators arrested two individuals and seized 800 servers from a web hosting company facilitating cyberattacks, interference operations, and disinformation campaigns. The scale of the seizure underscores the Netherlands' role as a frontline state in European cyber defense and sends a deterrent signal to hosting providers operating in gray zones.
Ukraine-Russia Cyber Conflict
Ghostwriter's targeting of Ukrainian government entities with Prometheus-themed phishing lures continues the pattern of sustained cyber operations against Ukraine since the February 2022 Russian invasion. The campaign aligns with broader Belarusian support for Russian strategic objectives, including intelligence collection and disruption of Ukrainian state functions. CERT-UA's public attribution underscores Kyiv's ongoing efforts to document and expose hostile cyber activity.
---
Recommended Actions
Immediate (0-24 hours)
1. Patch Cisco SD-WAN (CVE-2026-20127): Apply 25 February 2026 security updates to all Catalyst SD-WAN controllers and managers; audit logs since 2023 for compromise indicators.
2. Patch Cisco Secure Workload (CVE-2026-20223): Apply CVSS 10.0 REST API vulnerability patches within 24 hours; restrict API endpoint access to trusted networks.
3. Patch Drupal Core: Apply SQL injection patches immediately to all Drupal installations; review logs for exploitation attempts; implement WAF rules if patching is delayed.
4. Patch Trend Micro Apex One: Apply emergency patches for actively exploited zero-day; review server and endpoint logs for compromise indicators.
5. Patch Langflow (CVE-2025-34291): Apply patches for CVSS 9.4 origin validation flaw; review authentication logs for signs of exploitation.
6. Rotate AWS Credentials: If your organization interfaces with CISA or uses AWS GovCloud, verify credential integrity and rotate as precautionary measure.
High Priority (24-72 hours)
1. Patch Ivanti EPMM: Apply critical RCE patches; isolate EPMM servers from internet access; review logs for limited exploitation indicators.
2. Patch Microsoft WSUS: Apply out-of-band RCE update to all WSUS servers; verify servers are not internet-exposed; monitor for public PoC exploitation attempts.
3. Patch Ubiquiti UniFi OS: Apply maximum severity vulnerability patches to all UniFi devices; restrict management interface access to trusted networks.
4. Update React Applications: Apply React Server Components RCE patches to all applications using Next.js, Remix, or similar frameworks; review WAF logs for suspicious HTTP requests.
5. Review Cisco Email Gateway: Check Cisco advisory for compromise indicators on Secure Email Gateway and Email/Web Manager; implement interim mitigations until patch available.
This Week
1. Implement Secret Scanning: Deploy automated tools (GitHub Advanced Security, GitGuardian, TruffleHog) to detect credential exposure in code repositories.
2. Enhance Insider Threat Detection: Implement behavioral analytics to flag anomalous credential access, data downloads, or repository commits by privileged users.
3. Review Azure AD Security: If using Azure AD, baseline normal administrative tool usage and flag execution of ROADtools or similar reconnaissance frameworks from unexpected accounts.
4. Strengthen GitHub Security: Enable branch protection rules, mandatory code review, secret scanning, and require verified commits with GPG signatures to prevent supply chain attacks.
5. Audit SD-WAN and Edge Appliances: Inventory all F5 BIG-IP, Cisco SD-WAN, and similar edge infrastructure; verify patch status and management interface exposure.
---
Watch List
- FortiOS Vulnerability: High severity flaw disclosed 14 October 2025; monitor Fortinet PSIRT for CVE assignment and technical details.
- Unbound DNS Resolver: Multiple DoS vulnerabilities patched by NLnet Labs; apply updates to prevent service disruption.
- Iranian APT Activity: Monitor for additional Screening Serpens campaigns targeting defense and technology sectors; watch for AppDomainManager hijacking indicators.
- GitHub Supply Chain Attacks: Increased vigilance for malicious workflow injections following Megalodon campaign; monitor for base64-encoded commands in GitHub Actions YAML files.
- Ransomware Infrastructure Migration: Following First VPN Service takedown, monitor for ransomware groups migrating to alternative anonymization services.
---
Sources
- CERT-EU Security Advisories (2026-002, 2026-001, 2025-042, 2025-041, 2025-040, 2025-039)
- CISA Known Exploited Vulnerabilities Catalog
- BleepingComputer Security News
- The Hacker News
- Krebs on Security
- Unit 42 (Palo Alto Networks)
- Microsoft Security Blog
- CERT.BE (Belgium)
- Cisco Security Advisories
- Trend Micro Security Bulletins
- Drupal Security Advisories
---
*This report synthesizes threat intelligence from multiple authoritative sources as of 23 May 2026. Organizations should verify vendor advisories and apply patches according to their change management processes and risk tolerance.*
